Description
File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vulnerability than CVE-2022-31943.
Remediation
References
https://github.com/ming-soft/MCMS
https://github.com/ming-soft/MCMS/issues/42
Related Vulnerabilities
CVE-2020-7674 Vulnerability in npm package access-policy
CVE-2023-33962 Vulnerability in maven package io.jstach:jstachio
CVE-2018-19048 Vulnerability in npm package simditor
CVE-2019-11819 Vulnerability in maven package org.opencms:org.opencms.workplace.tools.accounts
CVE-2022-36083 Vulnerability in npm package jose-node-cjs-runtime